Getting Data In

Data upload from splunk ui is successful, but data is not appearing in search

jagdish0886
Explorer

Hi,
I have uploaded the data to splunk, but while searching the data doesnt appear, I have shared the screenshots as well. Can you please help here.
Index used - default
log file type - .log
search criteria - all time
Splunk version of docker - store/splunk/splunk:7.3

alt text

0 Karma
1 Solution

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

View solution in original post

0 Karma

jagdish0886
Explorer

I have got a solution:

default volume size is 5 GB in splunk for each of the container, either you need to increase the volume size (for path /var/lib/docker/volumes path on host machine of the docker containers ) or reduce the parameter value to lower the size in server.conf of each of the container:

refer below thread for more details:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

0 Karma

jagdish0886
Explorer

adding few more details:
When I upload the data from Splunk UI, it notifies that data is successfully uploaded, however
indexed data doesn't reflect in Splunk indexed data path opt/splunk/var/lib/splunk/spice-index/db and hence not searchable from splunk UI. Please help how to make the data searchable:

Index used: default and custom (both same issue)
search criteria: all time
splunk docker container: version store/splunk/splunk:7.3  developer licence
file size : 500 KB file type .log
browser: tried with chrome and IE
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...